CRISC Information Technology and Security Practice Question
A risk practitioner is evaluating the effectiveness of the organization's security awareness training program. The practitioner wants to determine whether the training is reducing the risk of phishing attacks. Which of the following metrics would be MOST indicative of the program's effectiveness?
⚠ Common exam trap
The trap here is choosing a metric that measures activity or outcomes (like training completion or breach counts) rather than a behavioral metric that directly reflects the likelihood of falling for a phishing attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The click-through rate on simulated phishing campaigns over time.
The click-through rate on simulated phishing campaigns is the most indicative metric because it directly measures employee behavior in response to phishing attempts. A declining click-through rate over time demonstrates that employees are learning to recognize and avoid phishing, which reduces the risk of successful attacks. Other metrics like completion rates or breach counts are either indirect or influenced by external factors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of phishing emails reported by employees to the security team.
Why it's wrong here
The number of reported phishing emails can indicate increased awareness, but it can also fluctuate based on attack volume. It does not directly measure whether employees avoid clicking on malicious links. Reporting is a positive behavior, but it alone does not prove that the training reduced the likelihood of successful phishing attacks. It is a useful metric but not the most indicative.
- ✗
The percentage of employees who completed the annual security awareness training.
Why it's wrong here
Completion rate measures compliance with training requirements but does not indicate whether employees can recognize and respond to phishing attempts. High completion does not necessarily correlate with reduced phishing risk. It is a lagging indicator of participation, not of behavioral change or risk reduction. Therefore, it is not the most indicative metric of effectiveness.
- ✗
The number of phishing incidents that resulted in a data breach.
Why it's wrong here
The number of breaches is a lagging indicator and is influenced by many factors beyond employee awareness, such as technical controls and attacker sophistication. A low number could be due to effective technical defenses rather than training. It does not isolate the effect of the training program, making it less indicative of its specific effectiveness.
- ✓
The click-through rate on simulated phishing campaigns over time.
Why this is correct
The click-through rate on simulated phishing campaigns directly measures employee behavior when faced with a phishing attempt. A decreasing trend over time indicates that employees are becoming better at recognizing and avoiding phishing emails, which directly correlates with reduced risk. This metric provides actionable insight into the effectiveness of the training program in changing behavior.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.